Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
PatchThe Events Calendar pluginWordPressOur summary
StellarWP has patched two unauthenticated remote code execution flaws in The Events Calendar plugin for WordPress: CVE-2026-78159 and CVE-2026-78006, both rated CVSS 9.8. The bugs can allow code or PHP object injection and could result in a complete WordPress site takeover when event comments are enabled. Administrators should update to The Events Calendar 6.17.4.1, as versions before 6.17.3.1 are exposed to both issues and CVE-2026-78006 is fixed in 6.17.4.1.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.